
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
Boffin: staff-engineer layer for AI coding agents. Routes per-edit architectural constraints and requires verification. Not a static AGENTS.md. Install: npx boffinit cursor
Boffin (npm: boffinit) is a staff-engineer control layer for AI coding
agents: it feeds the agent the architectural constraints for the exact file it
is editing and makes it verify the result -- DuckDB case study:
a guided refactor landed at +17 / -17 lines with 2,104 assertions passing.
You ask for a 15-line fix; the agent comes back with a 500-line renovation. Boffin gives the agent the architectural constraints that apply to the file it is about to touch, then makes it verify the result.
It is not another AGENTS.md and not a prompt pack. Those formats usually ship
one static instructions block for the whole repository; Boffin routes only the
constraints relevant to the current edit. Powered by ParselFire Core.
npx boffinit cursor
AGENTS.md-style one block for everything)Static rules file (AGENTS.md) | Boffin | |
|---|---|---|
| Delivery | Usually one static block for the whole repo | Constraints routed to the current edit |
| Verification | None required by the format | Required, proportional to the change |
| Evidence | Usually none | Recorded case studies with numbers |
The public case studies record these guided refactors on real open-source code:
+17 / -17; 2,104 assertions
across 8 test files passed; distinct continuation and recovery paths were
preserved.+16 / -33; 49 tests passed;
no public API change.These are reproducible case studies, not a controlled A/B benchmark.
Boffin requires Node.js 18 or newer.
Run from your project:
npx boffinit cursor
Run these inside Claude Code:
/plugin marketplace add MicSm/boffin
/plugin install boffin@boffin
Run these from a terminal:
codex plugin marketplace add MicSm/boffin
codex plugin add boffin@boffin
Codex does not trust plugin hooks automatically. Run /hooks once inside Codex
to review and trust Boffin's hooks; until then the plugin's skills work but the
automatic per-session activation stays off.
Run from your project:
npx boffinit opencode
Then open the project in OpenCode. Always-on guidance lands via
opencode.json -> .boffin/AGENTS.md. On demand: /boffin,
/boffin-review, or the boffin / boffin-review skills.
Install details, commands, and troubleshooting: OpenCode delivery.
Want the machinery? Read how ParselFire Core works.
Similar code is not always the same code. Boffin gives the agent a reason to stop before it merges a real special case, blurs a sync/async boundary, moves state away from its owner, or turns a focused task into a tour of the codebase.
The point is not to make the agent timid. It is to make the expensive details explicit before they become an interesting afternoon.
AGENTS.md is usually one static instructions file for the whole repository.
Boffin routes only the architectural constraints relevant to the file the agent
is about to edit, then requires a check proportional to the change.
Every rule ships in this repository as readable, versioned markdown under
packs/, and the packs are GPG-signed. Nothing is hidden at install
time: open any pack and read every rule before trusting it. At edit time Boffin
selects which of those rules apply to the file being touched. See
how ParselFire Core works for the routing map.
You ask for a small fix; the agent comes back with a renovation. Boffin injects the load-bearing constraints for the current file before the edit and forces verification afterward.
lite, full, and max change?They tune cleanup ambition, not correctness:
lite keeps cleanup pressure low and favors the smallest useful change.full is the balanced default.max applies the strongest cleanup pressure when the task justifies it.On plugin hosts, select a profile with /boffin lite, /boffin full, or
/boffin max. There is no off profile.
No. Every profile keeps the same early correctness stages and rejection rules, including trust-boundary validation, data-loss prevention, security, and accessibility requirements.
boffin: comments in generated code?boffin: marks are machine-readable audit tokens: they let you grep/harvest
which invariants held and which were refused across a codebase. Nothing is
sent anywhere; the payload is the invariant itself. Disable with one line:
create an empty .boffin-trace-off file at the repository root.
No. Boffin does not isolate processes, filter shell commands, or restrict filesystem or network access. It guides architectural decisions in generated code. Use command sandboxes and security controls for their own job; Boffin has a different job.
npx boffinit cursor uninstall
npx boffinit opencode uninstall
Each uninstaller removes that host's managed files only. Shared
.boffin/packs and .boffin/VERSION stay if the other host is still
installed. Unrelated project files are left alone.
No. It tells the agent which contracts deserve attention and requires external checks, but your repository's tests and review process remain authoritative.
Portable adapters cover hosts that read AGENTS.md, CLAUDE.md, workspace
rules, or repository instructions. See
host delivery and adapters for
the technical map.
Boffin is available under the MIT License. See credits.
npx boffinit cursor
FAQs
Boffin: staff-engineer layer for AI coding agents. Routes per-edit architectural constraints and requires verification. Not a static AGENTS.md. Install: npx boffinit cursor
The npm package boffinit receives a total of 14 weekly downloads. As such, boffinit popularity was classified as not popular.
We found that boffinit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.